Privacy Policy
Privacy Policy (2026.09.08)
S2W Inc. Privacy Policy
S2W Inc. (the "Company") establishes and discloses the following Privacy Policy pursuant to Article 30 of the Personal Information Protection Act, in order to protect the personal information of data subjects and to handle related grievances of data subjects promptly and smoothly.
1. Categories of Personal Information, Purposes of Use, and Retention Periods
The Company processes personal information for the purposes set out below, and does not use the personal information it processes for any purpose other than such purposes. If the purpose of use changes, the Company takes the necessary measures, including obtaining separate consent, pursuant to Article 18 of the Personal Information Protection Act. Once the purpose of processing has been achieved, the Company destroys the personal information without delay; where retention is required under applicable laws and regulations, the Company retains it for the relevant period.
① Directly Collected Items · Purposes of Processing · Retention Periods
| Category | Legal Basis | Purpose of Processing | Collected Items | Retention Periods |
|---|---|---|---|---|
| Membership Registration and Account Issuance (QUAXAR / XARVIS) [Required] | Article 15 (1) 4 of the Personal Information Protection Act (performance of a contract) | Membership registration and account issuance; provision of the Services (including requests for information, audit logs, search history, and user-specific services); development and improvement of new services | Password, email address (ID), name, affiliation (workplace, job title, department), contact details (telephone, mobile), Service usage information (requests, access IP addresses, usage history, timestamps, search terms), company security-related information, keywords of interest | Until three (3) months after withdrawal of membership and termination of the agreement |
| Website Inquiries and Access to Materials [Required] | Article 15 (1) 4 of the Personal Information Protection Act (performance of a contract) | Provision of requested information and materials (e.g., Analysis Reports); handling of inquiries and responding to complaints via email, telephone, and other means | Country, company/organization name, name, job title, email address | Destroyed without delay after the purpose of processing has been achieved (retained for the relevant period where retention is required under applicable laws and regulations) |
| Product Demo and Trial Requests [Required] | Article 15 (1) 4 of the Personal Information Protection Act (performance of a contract) | Processing product demo and trial requests, and providing related consultation | Product requested for demo, country, company/organization name, name, job title, email address, telephone number, industry, business type, preferred meeting/service start date, referral source, message, contact person | Until three (3) months from the end date of the product demo or trial |
| Event Participation [Optional] | Article 15 (1) 1 of the Personal Information Protection Act (consent) | Receiving, operating, and providing guidance on online and offline events | Country, company/organization name, name, job title, email address, telephone number, referral source | Destroyed without delay after the purpose of processing has been achieved |
| Marketing Use [Optional] | Article 15 (1) 1 of the Personal Information Protection Act (consent) | Online and offline marketing and advertising; delivery of product brochures, newsletters, and event information; provision of tailored content and advertisements (including webinar invitations) | Country, company/organization name, name, job title, email address, telephone number | Until consent to marketing use is withdrawn |
② Automatically Collected Information
In the course of using the Services, access logs, referral sources, time spent on pages, links clicked, search terms (including the time of search), access IP addresses, cookies, and similar information may be automatically generated and collected.
※ The Company does not collect sensitive information (such as ideology, beliefs, political views, and health information) or unique identification information (such as resident registration numbers).
③ Retention and Use Periods Required by Law
| Items Retained / Purpose | Retention Period | Legal Basis |
|---|---|---|
| Records on contracts or withdrawal of subscription | 5 years | Act on Consumer Protection in Electronic Commerce, Article 6; Enforcement Decree, Article 6 |
| Records on payment and supply of goods | 5 years | Act on Consumer Protection in Electronic Commerce |
| Records on consumer complaints or dispute resolution | 3 years | Act on Consumer Protection in Electronic Commerce |
| Records of website visits (access logs) | 3 months | Protection of Communications Secrets Act, Article 15-2; Enforcement Decree, Article 41 |
2. Provision of Personal Information to Third Parties
As a general principle, the Company does not provide or disclose users' personal information to third parties unrelated to the Services. However, the following cases are exceptions.
- Where an investigative agency so requests for investigative purposes in accordance with the procedures and methods prescribed by applicable laws and regulations
- Where the Company becomes obligated to submit personal information under applicable laws and regulations
3. Outsourcing of Personal Information Processing
The Company outsources personal information processing tasks as set out below in order to provide the Services smoothly.
| Entrusted Company | Outsourced Tasks | Retention and Use Period |
|---|---|---|
| Amazon Web Services Korea LLC | Website hosting, web services, data storage, and infrastructure management | Upon withdrawal of membership or termination of the outsourcing agreement |
| Lotte Innovate | Facility management of the systems used to provide the Services | Upon termination of the outsourcing agreement |
| S-1 Corporation | Office access security and system alarm management | Upon termination of the outsourcing agreement |
| Zoho Corporation Pte. Ltd. (Singapore; data stored at a U.S. data center) | Operation of the help desk (Zoho Desk) for receiving and responding to customer inquiries | Deleted upon termination of the outsourcing agreement, in accordance with the entrusted company's periodic deletion cycle and backup retention period |
When entering into an outsourcing agreement, the Company specifies in writing, pursuant to Article 26 of the Personal Information Protection Act, matters concerning the prohibition of processing personal information beyond the purpose of performing the outsourced tasks, technical and administrative protection measures, restrictions on re-outsourcing, management and supervision of the entrusted company, and liability including damages, and supervises whether the entrusted company processes personal information safely. If the outsourced tasks or the entrusted company changes, the Company discloses such change without delay through this Privacy Policy.
The status of Zoho Corporation Pte. Ltd.'s re-outsourcing (sub-processors) can be found in the list of sub-processors disclosed by Zoho (https://www.zoho.com/privacy/sub-processors.html).
4. Overseas Transfer of Personal Information
Pursuant to Article 28-8 (1) 3 of the Personal Information Protection Act, the Company transfers personal information overseas as set out below for the purpose of outsourcing the processing and storage of personal information necessary to enter into and perform contracts with data subjects, and discloses the details through this Privacy Policy.
| Item | Details |
|---|---|
| Personal information items transferred | Name, email address, telephone number, and information contained in inquiries |
| Country to which information is transferred | United States (Zoho data center) |
| Timing and method of transfer | Transmitted and stored via encrypted network communications upon receipt of a customer inquiry |
| Recipient | Zoho Corporation Pte. Ltd. ([email protected]) |
| Purpose of use | Receiving and responding to customer inquiries (provision of help desk services) |
| Retention and use period | Deleted upon termination of the outsourcing agreement, in accordance with the entrusted company's periodic deletion cycle and backup retention period |
| Method, procedure, and effect of refusing the transfer | Data subjects may request to refuse the transfer by contacting the Information Security Center (070-5066-5277 / [email protected]). If refused, receiving and responding to inquiries through the help desk may be restricted, and data subjects may contact the Company directly using the contact information above. |
If the transferred items, recipient country, or recipient changes, the Company discloses such change without delay through this Privacy Policy.
5. Department Receiving and Handling Requests for Access to Personal Information
Data subjects may submit requests to access, correct, delete, or suspend the processing of their personal information to the department below, and the Company handles such requests without delay.
- Department Receiving and Handling Requests: Information Security Center
- Contacts: 070-5066-5277 / [email protected]
6. Rights of Users and Legal Representatives and Methods of Exercise
- Users may at any time request to view, correct, delete, or suspend the processing of their registered personal information, or to withdraw their consent. Upon contacting the Company's personal information management department in writing, by telephone, or by email, the Company takes action without delay.
- If a user requests the correction of an error, the Company does not use or provide the relevant personal information until the correction is completed.
- The legal representative of a child under 14 years of age has the right to view, correct, delete, or suspend the processing of the child's personal information and to withdraw consent, and must include a power of attorney when contacting the Company.
- Personal information for which processing has been suspended, which has been deleted, or for which consent has been withdrawn is handled in accordance with "7. Destruction of Personal Information," and is not accessed or used for any other purpose.
- Users may refuse or request an explanation where a decision made solely through fully automated processing of personal information has a significant effect on their rights or obligations. The Company does not currently make any such automated decisions.
7. Destruction of Personal Information
- When personal information becomes unnecessary, such as upon expiry of the retention period or achievement of the purpose of processing, the Company destroys it without delay.
- Where personal information must continue to be preserved under other laws and regulations notwithstanding the expiry of the consented retention period or the achievement of the purpose of processing, the Company transfers it to a separate database or stores it in a different location.
- Destruction procedure: The Company selects the personal information for which grounds for destruction have arisen and destroys it upon approval from the Chief Privacy Officer.
- Destruction method: Electronic files are destroyed in a manner that renders them unrecoverable, and paper documents are destroyed by shredding or incineration.
8. Measures to Ensure the Safety of Personal Information
The Company takes the following measures to ensure the safety of personal information.
- Administrative measures: Establishment and implementation of an internal management plan, and regular employee training
- Technical measures: Management of access privileges, installation of an access control system, encrypted storage of passwords and unique identification information, encrypted communications, retention of access records and prevention of their forgery or alteration, and installation of security programs
- Physical measures: Access control for the computer room and data storage room
9. Operation of Automatic Personal Information Collection Devices (Cookies, etc.)
The Company uses cookies and similar technologies, such as web beacons, to provide tailored services. A cookie is a small text file that a website server sends to a user's browser and that is stored on the user's device. The Company uses cookies together with third-party tools, including Google Analytics, to analyze usage patterns, deliver advertisements, and manage traffic.
- Purposes of cookie use (by type):
- Strictly necessary cookies: Cookies essential for providing the services requested by users
- Performance (measurement) cookies: Analysis of service usage, performance, and design; error detection; and improvement of the user experience
- Functional (content personalization) cookies: Provision of a personalized environment by remembering usage patterns and preferences, such as language settings
- Advertising (behavioral advertising) cookies: Provision of interest-based advertising based on visit and usage history
- Method of refusal: Users may allow, be prompted about, or refuse the storage of cookies through their browser settings (Chrome: Settings > Privacy and security; Edge: Cookies and site permissions; Safari: Settings > Privacy). However, if the storage of cookies is refused, the use of some Services may be restricted.
10. Chief Privacy Officer
The Company designates a Chief Privacy Officer and a responsible department as set out below, in order to assume overall responsibility for matters relating to the processing of personal information and to handle inquiries and complaints from data subjects and provide remedies in connection with such processing.
| Category | Name / Title | Department | Contacts |
|---|---|---|---|
| Chief Privacy Officer | Hyunmin Suh / Director | Strategy Office | 070-5066-5277 / [email protected] |
| Privacy Officer | Daul Kim | Information Security Center | 070-5066-5277 / [email protected] |
11. Remedies for Infringement of Rights and Interests
Users may apply to the institutions listed below for dispute resolution or consultation in order to obtain remedies for infringement of their personal information.
- Personal Information Dispute Mediation Committee: 1833-6972 (www.kopico.go.kr)
- Personal Information Infringement Report Center: 118 (privacy.kisa.or.kr)
- Supreme Prosecutors' Office: 1301 (www.spo.go.kr)
- Korean National Police Agency: 182 (ecrm.police.go.kr)
12. Notification Procedures in the Event of a Personal Information Breach
If the Company becomes aware of the loss, theft, or leakage of personal information, the Company notifies data subjects without delay, pursuant to Article 34 of the Personal Information Protection Act and Articles 39 and 40 of its Enforcement Decree, of the items of personal information affected, the time and circumstances of the leakage, measures to minimize damage, response measures and remedial procedures, and the department and contact details for receiving reports, and reports the incident to the competent authorities where necessary.
13. Collection of Behavioral Information by Third Parties through Automatic Collection Devices
The Company collects and uses behavioral information through third-party tools, including Google Analytics, for the purposes of analyzing usage patterns and providing interest-based tailored advertising. The details are as follows.
- Items collected: Website visit and usage history (pages visited, time spent, clicks, search terms, etc.), device and browser information, and advertising identifiers
- Collection method: Automatic collection through cookies and similar technologies when users visit and use the Website
- Purpose of collection: Analysis of usage patterns and provision of interest-based tailored advertising
- Retention and use period: Destroyed 11 months from the date of collection (or destroyed without delay upon achievement of the purpose)
- Method of refusal: ① Blocking cookies in the browser (Chrome: Settings > Privacy and security > Third-party cookies; Edge: Cookies and site permissions; Safari: Settings > Privacy) ② The Google Analytics Opt-out Browser Add-on (tools.google.com/dlpage/gaoptout) ③ Opt-out tools for tailored advertising, including the DAA's "Browser Check," the EDAA's "Your Online Choices" (youronlinechoices.eu), and the NAI
14. Amendment of the Privacy Policy
This Privacy Policy applies from September 8th, 2026. If the contents of this Privacy Policy change, the Company discloses the changes and the effective date in advance through its website (https://s2w.inc/).
Current version: Ver. 2026.09.08 (updated revision). Previous versions are available in the version notice section of the website.